content: Required Content-Security-Policy headers needed to not break the application
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 35/100
- issue の種類
- ドキュメント
- 明瞭さ
- おおむね明確
- 活発さ
- 停滞
- 技術スタック
- react
調査の方向性
https://capacitorjs.com/docs/guides/security#web-view-security にある既存の Web View Security ガイドから始め、Ionic React PWA において報告されている default-src 'self' の動作を調査してください。報告されている読み込みおよび表示の失敗なしにアプリケーションが引き続き動作できるよう、必要な Content-Security-Policy ソース、特に style-src と script-src について文書化してください。
索引モデルが issue の本文から書いたものです。
説明
URL
https://capacitorjs.com/docs/guides/security#web-view-security
Issue Description
For additional protection against XSS attacks, I want to add Content-Security-Policy headers in my Ionic React application. I am, however, unable to figure out what Content-Security-Policies are required for the application to not break. The URL that I posted in this issue tells us to add a default-src 'self' tag, but when this tag is applied in a PWA, it breaks the larger part of the application. Components such as the search bar are no longer correctly displayed and the browser console shows some sources that cannot be loaded because of this 'self' tag. Even if I follow these instructions, I am not able to correctly include the different types of sources required in the Content-Security-Policies header for the application to completely work. Especially the style-src & the script-src tags need a configuration which is hard to figure out.
I believe it would be best to document some of the required Content-Security-Policy headers somewhere in the Ionic docs, so that people who want to secure their application further, can do this. I would assume that the answer to include all the inline script executions in the Content-Security-Policy headers is something that can be used on all Ionic React applications. This is why I think it would be best that it is documented somewhere.
- 主要言語
- MDX
- スター
- 621
- フォーク
- 3.2k
- 平均マージ
- 1日 2時間
- マージ済み PR(30日)
- 86
コントリビューションガイド
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
ionic-team/ionic-docs のほかの issue
-
content
難易度 2/5 1〜3時間 初心者へのやさしさ 86/100
ionic-team/ionic-docs#4705 ·
-
content package: angular
難易度 2/5 半日 初心者へのやさしさ 78/100
ionic-team/ionic-docs#4702 ·
-
triage
難易度 1/5 1時間未満 初心者へのやさしさ 80/100
ionic-team/ionic-docs#4546 ·
-
content: broken link オープンcontent
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
ionic-team/ionic-docs#4381 · コメント 2 件 ·
-
triage
難易度 1/5 1時間未満 初心者へのやさしさ 72/100
ionic-team/ionic-docs#3639 ·
ionic-team/ionic-docs の issue をすべて見る
似ている issue
-
Crush オープン
難易度 1/5 1時間未満 初心者へのやさしさ 85/100
catppuccin/catppuccin#3125 ·
-
Link Checker Report オープンautomated issue report
難易度 1/5 1時間未満 初心者へのやさしさ 95/100
-
難易度 1/5 1時間未満 初心者へのやさしさ 90/100
VoltAgent/awesome-design-md#469 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
KhronosGroup/glTF#2648 ·
-
難易度 1/5 1時間未満 初心者へのやさしさ 90/100
sccn/sccn.github.io#108 ·